{"id":22040,"date":"2026-09-25T10:36:24","date_gmt":"2026-09-25T10:36:24","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=22040"},"modified":"2026-09-25T10:36:24","modified_gmt":"2026-09-25T10:36:24","slug":"amazon-aws-certified-security-specialty-scs-c03-practice-test-questions-and-exam-dumps-part8-q141-160","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/amazon-aws-certified-security-specialty-scs-c03-practice-test-questions-and-exam-dumps-part8-q141-160\/","title":{"rendered":"Amazon AWS Certified Security &#8211; Specialty SCS-C03 Practice Test Questions and Exam Dumps Part8 Q141-160"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aws-certified-security-specialty-scs-c03-exam-dumps\"><b>Amazon AWS Certified Security &#8211; Specialty SCS-C03 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 141<\/b><\/h3>\n<p><b>Which AWS service can record DNS queries made by resources in a VPC for security investigation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route 53 Resolver query logging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Route 53 Resolver query logging can record DNS queries made from resources using the VPC DNS resolver. Security teams can use these records to investigate domain lookups, identify potentially suspicious destinations, and establish timelines during incidents. DNS query logs can be correlated with VPC Flow Logs, GuardDuty findings, and other security telemetry to improve investigation accuracy. Organizations should protect log destinations with appropriate IAM permissions and retention controls because DNS information can reveal sensitive details about application behavior and internal infrastructure.<\/span><\/p>\n<h3><b>Question 142<\/b><\/h3>\n<p><b>A company wants to prevent a user from creating an IAM role with permissions beyond an approved maximum. Which control should be applied to the role?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM permissions boundary<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPC endpoint policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network ACL<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS WAF rule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An IAM permissions boundary defines the maximum permissions that an IAM role or user can receive. Even if another identity-based policy grants additional actions, the effective permissions remain constrained by the boundary. This is useful when organizations delegate IAM administration while maintaining centralized privilege limits. A permissions boundary does not grant permissions itself, so the role still requires appropriate identity-based policies. Security teams should also review trust policies and other applicable controls because a well-designed boundary is only one component of secure IAM governance.<\/span><\/p>\n<h3><b>Question 143<\/b><\/h3>\n<p><b>Which AWS service can help automatically apply security policies to newly created accounts in an AWS organization?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Detective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Control Tower<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Macie<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Control Tower helps organizations establish and govern multi-account AWS environments using standardized account configurations and centralized controls. It can help apply governance requirements as accounts are provisioned within the managed environment. Control Tower works with AWS Organizations and other AWS services to support preventive and detective controls. This can reduce configuration differences between accounts and improve consistency. Organizations should still review controls regularly because governance requirements evolve, and account-specific workloads may require additional security configurations beyond the baseline controls.<\/span><\/p>\n<h3><b>Question 144<\/b><\/h3>\n<p><b>An investigator needs to preserve an EBS volume before making changes to a potentially compromised EC2 instance. What should be created first?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM user<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EBS snapshot<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudFront distribution<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An EBS snapshot can preserve a point-in-time representation of an EBS volume and can be useful for forensic analysis. During an incident, preserving storage evidence before modifying or terminating a compromised instance helps investigators maintain a reliable source for later examination. Access to snapshots should be tightly restricted and encryption should be considered according to organizational requirements. Investigators should document evidence-handling procedures and avoid altering the original evidence unnecessarily. Additional evidence, such as memory and network data, may also be required depending on the investigation.<\/span><\/p>\n<h3><b>Question 145<\/b><\/h3>\n<p><b>Which AWS service can provide centralized management of security groups across multiple accounts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Firewall Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Artifact<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Athena<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Firewall Manager can centrally manage supported security group policies across AWS accounts and organizational units. This helps organizations enforce consistent security requirements and reduce configuration drift in multi-account environments. Administrators can define policies that control or audit security group configurations according to organizational standards. Firewall Manager should be combined with appropriate network architecture and workload-specific rules because centralized policies do not eliminate the need for application-aware network controls. Regular review is also important to ensure policies remain aligned with legitimate connectivity requirements.<\/span><\/p>\n<h3><b>Question 146<\/b><\/h3>\n<p><b>A security engineer wants to detect changes to AWS resources and evaluate whether those changes violate organizational requirements. Which service is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon GuardDuty<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Config<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Shield<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Detective<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Config records resource configurations and provides configuration history that can help security teams understand how resources change over time. Config rules can evaluate current configurations against defined requirements and identify noncompliant resources. This makes Config useful for detecting configuration drift and supporting compliance monitoring. It is different from GuardDuty, which focuses on threat detection. Organizations can integrate Config findings with centralized security and remediation workflows so that certain violations trigger notifications, investigations, or automated corrective actions.<\/span><\/p>\n<h3><b>Question 147<\/b><\/h3>\n<p><b>Which AWS capability allows a workload to obtain temporary credentials by assuming an IAM role instead of storing permanent access keys?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS STS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon S3 Object Lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Config<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Security Token Service provides temporary security credentials for identities and workloads that need authorized AWS access. Applications and users can assume IAM roles and receive credentials that are valid for a limited session rather than maintaining permanent access keys. This reduces the risk associated with long-lived credentials and supports federation and cross-account access patterns. Security teams should define narrow role permissions, protect role trust policies, and monitor role-assumption activity. Temporary credentials should still be treated as sensitive while they remain valid.<\/span><\/p>\n<h3><b>Question 148<\/b><\/h3>\n<p><b>A company wants to restrict an S3 bucket so that only requests coming through a specific VPC endpoint are allowed. Which control can implement this requirement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudTrail trail<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 bucket policy with a VPC endpoint condition<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Shield protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An S3 bucket policy can use supported IAM condition keys to restrict access based on the VPC endpoint associated with a request. This allows organizations to establish a network-based data perimeter for sensitive S3 resources and prevent approved workloads from bypassing the intended private access path. The bucket policy should be carefully tested with legitimate applications and administrators. Additional controls such as IAM permissions, encryption, S3 Block Public Access, logging, and endpoint policies should be used to provide multiple layers of protection.<\/span><\/p>\n<h3><b>Question 149<\/b><\/h3>\n<p><b>Which AWS service can help detect sensitive information stored in S3 without requiring security teams to manually inspect every object?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Audit Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Network Firewall<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Macie provides automated sensitive-data discovery capabilities for Amazon S3. It can analyze supported S3 objects and identify data matching managed or custom data identifiers. This can help security teams locate sensitive information at scale and investigate potentially risky storage locations. Macie findings can contribute to broader data-protection workflows, but organizations must still enforce appropriate access controls and encryption. Automated discovery should be supplemented by data classification policies, retention requirements, monitoring, and periodic review of how sensitive information is stored and shared.<\/span><\/p>\n<h3><b>Question 150<\/b><\/h3>\n<p><b>Which service can provide a centralized view of AWS security findings while also supporting automated responses to those findings?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Security Hub<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon CloudFront<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Certificate Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Route 53<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Security Hub centralizes security findings from supported AWS services and integrated security products. It can also integrate with automation services such as Amazon EventBridge, allowing organizations to initiate workflows when findings meet defined conditions. This enables security teams to move from detection toward structured investigation and remediation. For example, a critical finding can trigger a notification or an automated response workflow. Security Hub should be configured with clear ownership, severity handling, and remediation procedures so that important findings are not overlooked.<\/span><\/p>\n<h3><b>Question 151<\/b><\/h3>\n<p><b>A security architect needs to encrypt application data efficiently while using a KMS key to protect the encryption material. Which technique should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Envelope encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Token-based routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Envelope encryption uses a data key to encrypt data and a separate key, commonly an AWS KMS key, to protect the data key. This architecture is efficient for large datasets because the application can perform local encryption operations with the data key instead of sending all application data directly to KMS. The encrypted data key can be stored alongside the encrypted data and later decrypted when authorized. Proper IAM permissions and KMS key policies are essential because unauthorized access to the wrapping key could expose protected data.<\/span><\/p>\n<h3><b>Question 152<\/b><\/h3>\n<p><b>Which AWS service can provide an immutable retention mechanism for important S3 records?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Athena<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Object Lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Config<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">S3 Object Lock provides protection against deletion or overwriting of objects during configured retention periods. It is useful for records that must be preserved for compliance, investigations, or security operations. Depending on the use case, organizations can configure retention settings or legal holds. Administrative access should be carefully controlled because users with inappropriate permissions may undermine other aspects of storage security. Object Lock should be combined with encryption, monitoring, restricted access, and appropriate lifecycle policies to create a comprehensive data-retention strategy.<\/span><\/p>\n<h3><b>Question 153<\/b><\/h3>\n<p><b>An organization wants to detect unusually high numbers of HTTP requests from a client and automatically restrict that traffic. Which AWS WAF feature is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rate-based rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 bucket policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS WAF rate-based rules can monitor request rates and apply an action when traffic exceeds a configured threshold. They can help mitigate certain types of automated abuse and high-volume HTTP request activity. The threshold should be based on legitimate application traffic patterns to reduce false positives. Rate-based rules can be combined with IP reputation rules, managed rule groups, and application-specific conditions. Security teams should monitor WAF logs and metrics after deployment so that rule behavior can be tuned without unnecessarily blocking legitimate customers.<\/span><\/p>\n<h3><b>Question 154<\/b><\/h3>\n<p><b>Which AWS service can help analyze whether an EC2 instance has network paths that expose it to unintended sources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Artifact<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Audit Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Inspector provides network reachability assessment capabilities for supported resources, helping security teams identify potentially unintended network exposure. Understanding reachability can add important context to vulnerability findings because a vulnerable resource that is reachable from an untrusted network may present a different risk than an isolated resource. Security teams can use this information alongside security groups, network ACLs, routing configurations, and vulnerability data. Remediation may involve restricting routes, changing security rules, or moving workloads into more appropriate network segments.<\/span><\/p>\n<h3><b>Question 155<\/b><\/h3>\n<p><b>Which AWS service can help organizations collect audit evidence from AWS environments against predefined control requirements?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Audit Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon GuardDuty<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Shield<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS WAF<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Audit Manager helps organizations collect and organize evidence for audit and compliance assessments. It can gather evidence from supported AWS services and map that information to controls within assessment frameworks. This can reduce manual evidence collection and provide a more structured view of compliance-related information. Audit Manager does not automatically guarantee compliance because organizations remain responsible for implementing, operating, and validating controls. Security and compliance teams should review collected evidence, address control gaps, and maintain documentation supporting the organization&#8217;s broader governance program.<\/span><\/p>\n<h3><b>Question 156<\/b><\/h3>\n<p><b>A security team wants to determine which API call created a new IAM access key during an investigation. Which source should be reviewed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS CloudTrail<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Shield<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Network Firewall<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS CloudTrail records API activity for supported AWS operations and can provide information about events such as IAM credential changes. During an investigation, analysts can search CloudTrail records to determine which principal performed an action, when it occurred, and what additional request context was recorded. This information can help establish whether credential creation was authorized or suspicious. Security teams should protect CloudTrail data against unauthorized modification or deletion and maintain appropriate retention so that historical events remain available when incidents are discovered later.<\/span><\/p>\n<h3><b>Question 157<\/b><\/h3>\n<p><b>Which AWS service can help centrally manage identities and permission sets for workforce users across multiple AWS accounts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS IAM Identity Center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Detective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Network Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS IAM Identity Center enables organizations to centrally manage workforce identities and assign permission sets across multiple AWS accounts. Instead of creating separate long-term IAM users in each account, organizations can connect an identity source and provide users with federated access. Permission sets define the level of AWS access assigned to users or groups. This model supports centralized identity lifecycle management and easier access reviews. Security teams should apply least privilege, strong authentication, and appropriate session controls when configuring workforce access.<\/span><\/p>\n<h3><b>Question 158<\/b><\/h3>\n<p><b>A company wants to prevent public access to S3 resources even if an administrator accidentally creates a permissive bucket policy. Which control should be enabled?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Block Public Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Transfer Acceleration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Select<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">S3 Block Public Access provides controls designed to prevent public access through certain bucket policies and ACL configurations. It is an important preventive safeguard against accidental exposure of S3 data. Organizations can apply Block Public Access at supported account and bucket levels to establish a stronger baseline. It should not replace IAM, bucket policies, encryption, monitoring, or data classification. Security teams should verify whether any legitimate public-use cases exist before enforcing restrictions broadly and should monitor configuration changes continuously.<\/span><\/p>\n<h3><b>Question 159<\/b><\/h3>\n<p><b>An organization wants to use a managed private certificate authority for internal TLS certificates. Which AWS service should it select?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Private Certificate Authority<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon GuardDuty<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Config<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Private Certificate Authority provides managed private certificate authority capabilities for organizations that need certificates for internal systems and applications. It can issue private certificates used for TLS, device authentication, and other certificate-based security requirements. A managed CA reduces the infrastructure burden associated with operating a private certificate authority independently. However, CA permissions must be tightly controlled because unauthorized certificate issuance can create serious security risks. Organizations should establish certificate lifecycle processes covering issuance, renewal, revocation, and monitoring.<\/span><\/p>\n<h3><b>Question 160<\/b><\/h3>\n<p><b>A security analyst receives a GuardDuty finding involving suspicious API activity. What should the analyst do before concluding that the finding represents a confirmed compromise?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable GuardDuty<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Validate the finding using additional evidence such as CloudTrail and related security telemetry<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Delete the affected resource immediately<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignore the finding if no service outage occurred<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security finding should be validated using additional evidence before analysts determine the scope and impact of a suspected incident. For a GuardDuty finding involving API activity, CloudTrail can provide relevant API events, while services such as Detective or Security Hub may provide additional context. Analysts should establish a timeline, identify the principal involved, examine affected resources, and determine whether the activity was authorized. Validation helps distinguish genuine incidents from expected behavior and supports better containment decisions while preserving useful forensic evidence.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Amazon AWS Certified Security &#8211; Specialty SCS-C03 Exam Dumps and Practice Test Dumps. &nbsp; Question 141 Which AWS service can record DNS queries made by resources in a VPC for security investigation? AWS WAF Amazon Macie Route 53 Resolver query logging Amazon Inspector Correct Answer: 3 Explanation Route 53 Resolver query logging can [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22040"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=22040"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22040\/revisions"}],"predecessor-version":[{"id":22041,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22040\/revisions\/22041"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=22040"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=22040"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=22040"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}